Tuesday, September 2, 2014

“Airtight” Online “Terms of Use” via Clickwrap or Browsewrap

Do you know the differences between a “clickwrap” agreement and a “browse-wrap” agreement?  If you don’t, you might be unable to enforce your website’s “terms of use.”  In either case, it might be time to redesign your Website’s legal links to ensure they are valid contracts enforceable against your users.

In a recent decision, the U.S. Court of Appeals for the Ninth Circuit upheld an earlier ruling (Nguyen v. Barnes & Noble, Inc., USDC, C.D. California, Aug. 28, 2012) that an online customer at an e-commerce website did not agree to the website’s terms and conditions governing website use and sale of goods, even though there was a conspicuous hyperlink on every page to the website’s “Terms of Use.”   Nguyen v. Barnes & Noble, Inc. (9th Cir. Aug. 18, 2014).  The court held that the user never gave valid binding consent to arbitration or choice of law terms, because (1) the user did not click on the “Terms of Use”, (2) there was “no notice to users” that they were entering into a contract by using the website, and (3) there was no prompt to users to take any affirmative action to demonstrate assent to formation of a contract.  As a result, the website owner was unable to rely upon the Terms of Use, and the consumer was entitled to sue in court for claims arising out of a failed online commercial purchase.

For website users, the decision encourages never clicking on any hyperlinks relating to “terms of use”, “privacy,” “legal conditions” or other hyperlinks customarily posted by website owners.  For website owners, the decision is a wake-up call to immediately change the layout and functioning of the “terms of use,” “legal conditions,” “privacy” and other warnings.

In Nguyen, the court reminded the parties that there are only two flavors of contracts formed on the Internet.

  • Under “clickwrap” (or “click-through”) agreements, website users are required to click on an “I agree” box after being presented with a list of terms and conditions of use.
  • Under “browse-wrap” agreements, a website’s terms and conditions of use are generally posted on the website via a hyperlink at the bottom of the page, but there is no functionality requiring the user to manifest assent to the terms and conditions expressly.  Because there is no affirmative duty to express such assent, the determination of the validity of the browse-wrap contract depends on whether the user has actual or constructive knowledge of the website’s terms and conditions.  (Such knowledge may be presented on the website or may be given later, in the form of a mailed notice of breach and demand for cure.  Without such knowledge, there is no online contract.

The Nguyen decision did not address whether the website user is deemed to have assented to the website’s privacy policy.   However, the same principles could apply if the user were to argue that she had no actual knowledge of the privacy policy and never assented to the use of cookies, pixel tags, metadata analysis, profiling or other clandestine surveillance, or the re-transfer of personal information to third parties.

To ensure actual consent, the Court warned that “the onus must be on website owners to put users on notice of the terms to which they wish to bind consumers.”  Website owners now must be more “aggressive” or “unfriendly” by giving “actual notice” of the terms and demanding either a clickwrap or a browse-wrap agreement.  “User experience” (“UX”) engineers must now find solutions to keep the website user engaged and in a positive mood, while ensuring that the user is aware of the terms of use and consents to such terms.

One solution involves delaying an “I agree” button (or a display of actual terms of use) until the user is ready to make a purchase or submit information.  But that probably is too late, since the website owner will want to keep any dispute (even as to pre-purchase website usage) out of court and limited to applicable law and a chosen arbitral forum.

Another solution is to force a “pop-up” “I consent” when the user wants to leave the home page.  This could work for privacy matters as well so long as no customer profiling information (from cookies, etc.) were collected at the landing page.  That would require a change in search engine optimization and metatagging customs.  Or “Privacy” might be incorporated into “Terms of Use” to reduce the number of “approval” clicks by users.

A third solution might involve displaying a “Website Terms of Service” button that states “By clicking here, you are indicating that you have read and agree to the Terms of Service.”

The bottom line: “Whether a user has inquiry notice of a browsewrap agreement,  in turn, depends on the design and content of the website and agreement’s webpage.”  Slip opinion, p. 12.  This decision invites everyone to review and perhaps to redesign the legal framework for their online website-based legal agreements.

Friday, May 16, 2014

EU’s Judicial Ruling on “Right to be Forgotten” (Takedown Rights) for Claims by Individuals against Search Engines, and Implications

A recent ruling by the Court of Justice of the European Union (CJEU) has potentially far reaching implications for data privacy in support of an individual’s “right to be forgotten” online both inside and outside the European Union.  Google Spain SL, Google Inc. v Agencia Española de Protección de Datos (AEPD), Mario Costeja González (CJEU, May 13, 2014).

It raises serious liability issues for every Internet search engine and international data collection company. To the extent that increased compliance costs will be passed on to advertisers, the opinion increases the cost of doing e-business with EU customers and could increase prices for consumers.

Responsibilities of A Search Engine as a “Data Controller” under EU Privacy Law.  In the case in Spain, which prompted this ruling, a man requested that Google Spain remove the links to old newspaper articles, lawfully published, which were no longer relevant to his situation, but could create a negative impression of him when read.  Google refused, claiming that a search engine creating links to the content of other websites is not the “data controller” but merely an intermediary in relation to third party websites and could neither monitor nor remove this data.

In addition, Google alleged that it was not subject to the 1995 EU Data Protection Directive because its search engine was in the US and it did not have a nexus on EU soil.  Google Spain’s office only sold advertising.

The Spanish court ordered Google to remove the links. Google appealed and the court referred the case to the CJEU for an opinion.  In summary, the CJEU opined:

1) Jurisdiction.   Google was subject to the EU’s jurisdiction because the processing of the data was carried out in the context of the activities of its subsidiary located in Spain and directed at EU member states.

2) Redefinition of “Data Controller.”  Google is indeed a “data controller” because while it just processes the data, even more than third party sources, it controls the dissemination of the data and therefore plays the key role in how such information (already available on other websites) affects the personal privacy and data protection of the individual, making it subject to the EU Directive.

3) Right to be Removed from a Search Engine (sometimes, “the right to be forgotten”). The fundamental rights of the individual to privacy and data protection override the right of Google for economic gain and the right of the public to access this information unless it is in the public interest to do so (as in the case of a public figure).  The individual should be entitled to go to search engines and request that links that were “inadequate, irrelevant or no longer relevant” be removed.

Impact within the EU.
Impact on Search Engines. The decision will reduce the ability of search engines to publish links to personal data of complaining European nationals, will add operating costs for search engines and potentially increase litigation where search engines refuse to “take down” personal data about ordinary citizens.

Impact on EU Data Protection Authorities.   The Google Spain  decision will require each European Data Protection Authority to balance policy factors of free speech versus personal privacy.  This will result in costly, complex and policy-based decisions by administrative bodies, a nightmare for both administrators and litigants.

Impact on Non-EU Web Services Companies.
Jurisdiction.  If you have a “sales subsidiary” in an EU country, your e-commerce operations will now be subject to the full direct application of EU data protection and personal privacy rights, even though your servers, operations and accounts are outside the EU.  The concept of EU judicial jurisdiction over foreign companies in data protection and privacy now looks analogous to broad U.S. federal constitutional limits on judicial jurisdiction, where your “presence” plus your “purposeful availment” of activities in a foreign state will subject you to the jurisdiction of the foreign state under “long arm” statutes.  If there was any doubt, it is now clear that running an e-business globally will subject you to local long-arm jurisdiction on data protection and privacy.  The irony here is that you might be properly outside the taxing jurisdiction (under traditional norms of international jurisdiction within the definition of a “permanent establishment” in tax treaties) while being subject to long-arm jurisdiction for regulatory compliance and privacy torts in a foreign jurisdiction.

Vicarious Liability of the Search Engine as Data Controller without Primary Liability of the Offending Websites whose Sites are Linked by the Search Engine.   One key irony of this decision is that the website publishing the “offensive” “personal data” is not mandated to take down the individual’s “personal data,” but that the search engine that multiplies the number of people who access such content is deemed the “data controller” held liable to honor the “fundamental rights” of the individual.  The ruling imposed vicarious liability for making links but not direct liability for publishing the “private” personal information.

Developing Best Practices for Compliance.   Assuming a search engine accepts a takedown notice as a matter of policy, how can it comply?  How can it be certain that the complaining individual is entitled to a takedown?  If any discretion is involved, it will gum up web commerce.  If no discretion is involved (and one can make new rules that favor takedowns), the technology that allows “opt-outs” and “unsubscribes” can be reconfigured to allow takedown notices.  But the costs of verification of the identity of the affected party will have to be borne by someone, and the decision is one more step towards balkanization of the Internet for free speech and e-commerce.

Impact on US-EU Free Trade.   Privacy law has become a trade barrier of sorts.  The CJEU decision interferes with attempts at harmonization of privacy rights under the pending negotiations for the Transatlantic Trade and Investment Partnership between the US and the EU.  To the extent the Data Protection Directive (1995) and the proposed “General Data Protection Regulation” fail to provide some form of US safe haven (beyond the existing one), the Google Spain decision will likely promote more compartmentalization, less international commerce in data processing services and more localized separate computing environments (e.g., a local “EU Cloud”).

Penalizing the Wrong Business.   The Google Spain decision on data protection and privacy gives preference to privacy rights over freedom of expression.  It punishes the business that links Internet searchers to a validly published Internet website. It adopts a bludgeon against the business that scrapes information from other websites, not the “offending” websites.   The decision punishes the wrong business.

Monday, April 21, 2014

Big Data, Big Abuse Potential

SMAC, n.  (1) a variation of crack-cocaine; (2) a highly addictive, volatile, potentially life-transforming multi-composite drug, sometimes used illegally, universally available in medicine, commerce, education, and family economics; (3) social, mobile, analytics and cloud computing; (4) Big Data.

On April 11, 2014, the U.S. Federal Trade Commission (FTC) announced a public “workshop” on September 15, 2014, to examine effects of Big Data on “low income and underserved consumers.”  The workshop invites comments, reports, and original research to explore current practices in the uses of Big Data on high-income consumers and privacy rights generally.  The FTC will explore concerns that been raised about whether Big Data may be used to categorize consumers in ways that may affect them unfairly, or even unlawfully. (For more info, visit their website.)

The workshop will address consumer protection issues that could result in new regulations or laws affecting virtually all companies (whether or not they are “tech companies):

How are organizations using Big Data to categorize consumers?

What benefits do consumers gain from these practices? Do these practices raise consumer protection concerns?

What benefits do organizations gain from these practices? What are the social and economic impacts, both positive and negative, from the use of Big Data to categorize consumers?

How do existing laws apply to such practices? Are there gaps in the legal framework?

Are companies appropriately assessing the impact of big data practices on low income and underserved populations? Should additional measures be considered?

This workshop comes after the FTC examined privacy issues associated with big data practices in its 2012 report Protecting Consumer Privacy In An Era of Rapid Change: Recommendations for Businesses and Policymakers, and its ongoing examination of the data broker industry.

The proliferation of smart phones, tablets, intelligent mobile devices (including wristbands, headphones, automobiles and wearable telecom devices) and online social media have enabled the collection and analysis of huge datapoints.   The Internet of Things will include sensors (some of which are mobile) that are collecting data streams in real time.  Data brokers collect different related information that can be assembled into a mosaic of demographic information that might include race, religion, national origin, sex, sexual orientation, health conditions (subject to HIPAA), disability, veteran status and other commercially “relevant” criteria.  Big Data thus enables the pinpoint analysis of individual conduct as well as the conduct of individuals according to demographic, geographical, financial, educational and economic variables.

The FTC is looking at issues of the use of insights from Big Data (including credit risk scores, demographic information and other assessments) for illegal purposes.  While the FTC has been clear about potential abuses by financial institutions, the issues apply to all companies using Big Data.

Business executives (and law departments) should be asking how their own practices of collecting, analyzing and using Big Data might be abusive or illegal.

Now is a good time to conduct an internal review of your Big Data strategies.

What criteria do you use for market segmentation?  Consider how you use any Big Data (or direct customer data) in a manner that might discriminate against certain demographics in pricing, new product availability, service priority, credit card lines of credit, retirement account services, financial services, volume discounts, “early bird” or “favored customer” sales.

What criteria do you use for making preferential offers?  Do you limit access to “unfavored” customers in terms of access to higher quality products, services or content?

What policies do you have that might create (intentionally or not) a “disparate impact” (which, under one theory of law enformceemnt, constitutes intentional wrongful discrimination)?

Have you integrated your Big Data initiatives with your corporate social responsibility (CSR) and governance, risk management and compliance (GRC) programs.

Wednesday, March 5, 2014

Darwinian Survival through Disaster Recovery and Information Governance

It seems like stock prices fall pretty quickly after a data security breach.   Just ask TJ Maxx, Target, Nieman-Marcus or Sears.   The big boys probably have their business continuity plans (BCP’s) and information governance rules.   What about you?  What’s it all about, Alfie (the CEO, CIO, GC or Webmaster or Board member)?

My dalliance with BCP and “disaster recovery’ (“DR”) started 15 years ago, when I was negotiating long-term outsourcing contracts for enterprise customers.   No BCP/DR, no deal.

Fast forward to 2014.   Now just about everyone understands BCP/DR, requires it in their cloud computing agreements and maybe even in their strategic supplier agreements for manufacture of consumer packaged goods, or whatever.  So it’s time to reinvent and look at “information governance” as a subset of BCP/DR strategy.   And everyone MUST do something about “information governance” because you can get sued, pay a lot of money and lose customers.   Did I mention you (if you are a senior officer) might get fired? 

With your job on the line, where’s the crib sheet for mastering “information governance” and building your own job security plan (“JSP”)?

First step, sound the alarm and look for a BCP.  A business continuity plan acts like the Internet: multiple nodes, multiple points of failure, resiliency.  You plan your own company’s exit (and stresses leading to exit).

Second step, focus on an information governance strategy as a mini-BCP, directed at information technology, telecom and data security, brand management and liability management (to cut your losses on “stray” or “hacked” data).  Throw in a privacy policy too, with a compliance officer to run the deal.

Here’s the plan:
  • Face the music.  You won’t hear Beethoven, Mozart or Handel being mentioned with Gramm-Leach-Bliley, Obama(Care), or the less eponymous laws like HIPAA, HITECH or regulations on banking, financial services or insurance (“BFSI”).  Frame your frameworks.
  • Do some yoga.  A little flexibility, a little strength and resilience will help your company deal with surprise encounters of the info management kind.
  • Round up your data, Cowboy!/Cowgirl!.  Identify sources, uses, flows, warehousing, processing and transmittal of data.
  • Put your data collection on a diet.  Imagine a Web without intrusive cookies (as the EU regulators are considering due to easy identification of individuals with geolocalization tools).  Collect and keep personal data (and data leading to individual identification) only if you “need” it.   Otherwise, it’s digital baggage that, if hacked, will cause legal and branding hassles.
  • Orchestrate your musicians. 
    • Identify “records custodians.” 
    • Designate an “information governance team” for all managers who will have inputs into information management and technologies.
    • Designate an “incident response team” and allocate roles, responsibilities and strategies for each team member.   Include HR, IT, marketing, legal, purchasing, compliance, finance and
  • Get political.
    • Identify all of the company’s constituencies who may be impacted by an “incident.”  Consider suppliers, licensors, licensees, customers, joint venture partners, regulators, public relations, reporters, shareholders, directors, officers, employees, lenders, courts, litigants, and anyone else affected by your business.  
    • For “B corporations,” consider your social and environmental mission and constituencies.
  • Unchain your paranoia.  Assess vulnerabilities and mitigate risks.
  • Virtualize and diversify your supply chain (through to your customer delivery service too).  Identify and plan for “disaster” scenarios and the impact on operations, legal compliance, customer loyalty and the company’s value chain.
  • Treat data like gems and rare anti-venom snake serum.  For legal issues, the plan should address preservation of legal records and evidence, engagement of forensic analysts and timely statutory notifications of security breach incidents.
  • Party hearty, but only after you successfully do your mock “disaster” (“incident”).  The “incident response team” must practice the “table top exercise” drill of data recovery, data security breach notifications and remedial public relations.
  • Be democratic.  Get everyone involved, trained and conscious.
  • Adapt.  Evaluate and continuously monitor the data security practices and compliance of your internal and external tech providers.  Revise your policies to adapt to new threats and scenarios.  Get a trip to the Galapagos Islands and see what adaptive survival looks like.
Sometimes looking at digital life in analog form makes good sense. Stay healthy.

Wednesday, February 12, 2014

Your Global Brand: Reconciling Business Models and Supply Chains

On Abe Lincoln’s birthday, we can derive inspiration from the life and lessons of “Honest Abe.” Like your parents told you, you are known by the company you keep.  This is true for each employee in a service business as well as the entrepreneur, the growing business and the global business.   Your business model and your associations with others directly impact your business success.  Increasingly, you need to orchestrate your business operations and branding messages across both individual and shared brands.

Now, more than ever, creating and managing your global brand is essential to all aspects of your business, beyond attracting and retaining loyal customers under an understood trademark.  Every business today is a service industry, and your brand reflects quality of service and user experience (UX) for everyone who touches your business.

Value Chain Branding.  Brand management means running all aspects of your business as a strategic relationship throughout the entire business value chain. Your global brand transcends across customers, employees, suppliers, outsourced service providers, investors, professional advisors and even regulators and competitors. Think of the benefits of a strong brand in terms of strong corporate culture, employee morale, investor confidence and enterprise sustainability.

Proprietary vs. Shared Brands.   In the American culture, individualism and community can collide.  A proprietary brand is owned, controlled and managed by one enterprise.   A “shared brand” is the brand of shared enterprise.  The logic of collective action suggests that individuals and small and emerging businesses should brand themselves uniquely, while joining in shared brands that may include competitors and suppliers.

Managing Your Own Brand.   In the individualistic enterprise model, managing your own brand requires trademark registration in relevant markets (including countries where you source your products and services).  Think Coca Cola®

Sharing a Brand.   The Big Four accounting firms and the global law firms might present themselves as partnerships, but they  segregate their operations for tax, legal and regulatory purposes by setting up a common brand and then licensing it to themselves.  That’s sharing a brand at the individual enterprise level.  The leaders develop the concept, the membership follows the model and markets under the shared brand. Think Ocean Spray®, a cooperative of growers of cranberries.

Sharing a brand normally means losing your individual identity.   Ironically, in the services industries, the value of a shared brand depends on the quality and integration of the components (individuals) operating under that brand.  By marketing and delivering your own unique skills, doing your own blog and having your own little team within a larger organization, you can enjoy both the economies of scale of the larger organization and the unique profile that attracts and sustains your own clientele.  For this reason, broker-dealers, law firms, consulting firms and other service enterprises encourage each individual to be a rainmaker with unique talents and to team with others offering collective and synergistic talent.

Co-Branding.  Consider possible solutions to piggy-back upon the goodwill of others:

  • Creating new venues by co-marketing (under different brands) of different goods and services to the same target clientele.
  • Advertising to your target clientele in venues that your competitors do not use.
  • Giving financial incentives to referral sources by “partner referral” or “business partner” programs.
  • Earning a “certification” from a well-respected source of trust, such as a top university or the International Standards Organization, or other non-profit or non-governmental organization.
  • Participating in the development of industry standards.
  • Building a new trademark and enlisting others to sell under it, either as licensees, franchisees or even as co-owners of the brand.
  • Becoming a strategic advisor or “resident” expert to a university, think tank, startup incubator or non-profit organization.

Interplay of Individual Brand and Your Supply Chain.  Sharing a brand can also mean building a network of trusted suppliers and service providers who are the back-end of your service delivery platform.  You need to manager your suppliers to ensure you deliver on your promises (and your regulatory compliance obligations).   Otherwise, you have no business, and you have legal liability for breached contracts.  Think about your vendor contracts and your supply and service contracts for your customers.

Joint Ventures, Strategic Alliances and Teaming.  Synergies also come from collective operations that are either new enterprises or an extension of your own enterprise using third parties as co-providers or as suppliers.  Dow Corning has been a joint venture for over 40 years and has developed its own customer.  CSC (US) just announced a partnership with HCL (India) that enables CSC to deliver data center management and cloud computing using HCL as supplier and HCL can enjoy the benefit of CSC’s sales and customer relationships.  Think about introducing a strong “partner” to return and engage clients.

Rethinking your Brand Strategy.   Effective branding strategies bear fruit upon sale of the company, since trademarks and goodwill are valuable marketable assets that can be sold separately (like Abercrombie and Fitch) or as part of a business.  These distinctions might help you rethink your brand strategy and develop and support multiple brands for yourself.

P.S.  I’m being interviewed on the relationship of business models and global brand management tomorrow at 2 PM ET, at www.global-reach.com